JS.MonoGlyphRAT: Targeted Phishing Campaign Against US Enterprises
Threat actors are executing a targeted social engineering campaign against US-based enterprise environments using fraudulent business documentation, including fake purchase orders and Requests for Proposals (RFPs). The attack vector utilizes malicious JavaScript (.js) loaders embedded within these attachments to deploy the JS.MonoGlyphRAT, a sophisticated Remote Access Trojan designed for stealth and evasion of signature-based detection mechanisms. Upon execution, the malware establishes persistence through Windows Registry modifications or Startup folder manipulation and initiates command-and-control (C2) communication. This campaign facilitates unauthorized remote system access, lateral movement, and potential corporate data exfiltration within compromised networks.